ATT&CKReferencesTrend Micro KillDisk 2

Trend Micro KillDisk 2

Gilbert Sison, Rheniel Ramos, Jay Yaneza, Alfredo Oliveira. (2018, January 15). KillDisk Variant Hits Latin American Financial Groups. Retrieved January 12, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareKillDisk

KillDisk has called GetCurrentProcess.

T1083
File and Directory Discovery
MalwareKillDisk

KillDisk has used the FindNextFile command as part of its file deletion process.

T1134
Access Token Manipulation
MalwareKillDisk

KillDisk has attempted to get the access token of a process by calling OpenProcessToken. If KillDisk gets the access token, then it attempt to modify the token privileges with AdjustTokenPrivileges.

T1489
Service Stop
MalwareKillDisk

KillDisk terminates various processes to get the user to reboot the victim machine.

T1529
System Shutdown/Reboot
MalwareKillDisk

KillDisk attempts to reboot the machine by terminating specific processes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.